Nodectra
Back to NodectraLegal · Last updated 1 September 2026

Privacy Policy

This notice explains which personal data Nodectra uses to provide accounts, engineering workspaces, billing and secure access to the service.

1. Who is responsible for your data

Nodectra is the service name used by the operator identified in your order, subscription or commercial agreement. The operator acts as controller for account, billing and service-security data. Organizations using Nodectra may separately act as controllers for personal data they place inside their engineering projects.

Privacy questions and requests can be sent to privacy@nodectra.com. The operator's complete registered details must also be provided in the applicable commercial documentation.

2. Data we process

  • Account data: name, email address, authentication method, profile image and account status.
  • Organization data: organization name, memberships, roles and seat assignments.
  • Workspace data: projects, revisions, object configuration, approvals, deployments and audit records created by users.
  • Security data: sign-in events, rate-limit identifiers, verification and password-reset events, and technical request information needed to protect the service.
  • Billing data: subscription status, plan and Stripe customer, checkout and webhook identifiers. Nodectra does not store complete payment-card details.
  • Support data: messages and information you provide when requesting assistance.

3. Why we use the data

We process account, workspace and subscription data to create and perform the service contract; security and audit data to protect accounts, infrastructure and legitimate business interests; and billing or transaction records where required by accounting, tax or other law. Where an optional feature legally requires consent, you may withdraw that consent without affecting earlier lawful processing.

4. Google sign-in

If you choose Google sign-in, Google provides Nodectra with the verified email address and basic profile information permitted by the sign-in flow, such as your name, profile image and provider account identifier. Nodectra does not receive your Google password. Google processes the authentication step under its own terms and privacy policy.

5. Service providers and transfers

Data may be handled by infrastructure and database hosting providers and, when the relevant feature is enabled, by Google for authentication, Resend for transactional email and Stripe for billing. Access is limited to what each provider needs to deliver its service. Some providers may process data outside the European Economic Area using the safeguards applicable to their service and contract.

6. Retention

Account and workspace data is retained while the account or organization uses Nodectra and afterwards only for the period needed for recovery, security, dispute handling or legal obligations. One-time verification and reset tokens expire after one hour. Security, billing and audit records may be retained longer where needed to establish what happened or comply with law. Backup copies are removed through the applicable backup lifecycle.

7. Cookies and local storage

Nodectra uses strictly necessary authentication and security cookies to keep users signed in and protect account flows. The interface also stores the selected light or dark theme in browser storage. The current service does not use advertising cookies. If optional analytics or marketing technologies are introduced, this notice and any required consent controls will be updated first.

8. Security and engineering agents

Nodectra applies access control, organization isolation, protected credentials, signed deployment packages and audit records. No online system can guarantee absolute security. Project agents prepare proposals inside a bounded project context; their changes require a human approval step before application and do not make legal or similarly significant decisions about individuals.

9. Your rights

Depending on the circumstances, you may request access, correction, deletion, restriction, portability or object to processing. You may also withdraw consent where consent is the legal basis. Requests can be sent to the privacy address above. You may lodge a complaint with your competent supervisory authority; in Poland this is the President of the Personal Data Protection Office (UODO).

10. Changes

We may update this policy when the service, providers or legal requirements change. The date at the top identifies the current version. Material changes will be communicated through the service or another appropriate channel.

© 2026 Nodectra
Privacy PolicyTerms of ServiceSign in